StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
757
of 17,787 indexed, latest versions
Container images
786
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 757 of 17,787 indexed charts deploy, on 786 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+83 more65.5.1755
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

757 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,577
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,677
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

786 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
65.5.1
22
oomk8s/readiness-check:2.0.2875814cc853d
setuptools@40.8.0
python-pip@8.1.1-2ubuntu0.4
python-setuptools@20.7.0-1
65.5.1
8.1.1-2ubuntu0.6+esm3
20.7.0-1ubuntu0.1~esm1
11
codeurjc/server:v1.0310bea5b1ee7
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
8
oomk8s/readiness-check:2.0.07daa08b81954
setuptools@39.0.1
python-pip@8.1.1-2ubuntu0.4
python-setuptools@20.7.0-1
65.5.1
8.1.1-2ubuntu0.6+esm3
20.7.0-1ubuntu0.1~esm1
6
cachethq/docker:2.3.15a61ff0f67ea7
setuptools@33.1.1.post20171031
65.5.1
4
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
4
ncsa/checks:1.0.1cc46a03e16ed
setuptools@57.5.0
65.5.1
4
quay.io/strimzi/operator:0.37.052f376e64b9b
setuptools@39.2.0
65.5.1
4
argoproj/argocd:v1.8.1830e86cacefd
setuptools@40.8.0
65.5.1
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
setuptools@57.5.0
65.5.1
3
dpage/pgadmin4:6.12781369df9994
setuptools@52.0.0
65.5.1
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
setuptools@49.6.0
65.5.1
3
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
setuptools@46.1.3
65.5.1
3
paulkellerman/resultserver-app:1.0381eeccb0618
setuptools@65.5.0
65.5.1
3
paulkellerman/webserver-app:latest5a37b74f61b9
setuptools@65.5.0
65.5.1
3
selenium/hub:3.141.5902f251d48d5f
setuptools@45.2.0-1
45.2.0-1ubuntu0.1
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
setuptools@57.5.0
65.5.1
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
setuptools@40.8.0
65.5.1
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
3
amancevice/superset:0.35.212a0a9e66550
setuptools@44.0.0
65.5.1
2
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
65.5.1
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
setuptools@40.6.3.post20190116
65.5.1
2
aquasec/kube-hunter:0.6.8e64fe49f059f
setuptools@57.5.0
65.5.1
2
architectminds/aws-kubectl:1.19735e59a1085
setuptools@41.0.1
65.5.1
2
blakeblackshear/frigate:0.11.18330b0a265b8
setuptools@52.0.0
65.5.1
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
setuptools@50.3.2
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
65.5.1
0:3.9.16-1.module+el8.8.0+20025+f2100191.2
0:50.3.2-5.module+el8.8.0+21635+a173a6fa
2
confluentinc/cp-zookeeper:latest7610a50b13e7
setuptools@39.2.0
65.5.1
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
setuptools@39.2.0
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
65.5.1
0:3.9.16-1.module+el8.8.0+20025+f2100191.2
0:50.3.2-5.module+el8.8.0+21635+a173a6fa
2
datawire/aes:1.14.48588eafe6862
setuptools@50.3.2
65.5.1
2
devopsjourney1/mywebapp:latestbd1ec6838570
setuptools@57.5.0
65.5.1
2
gradiant/spark:2.4.4-python-alpine97657d56e927
setuptools@41.6.0
65.5.1
2
hjacobs/kube-ops-view:20.4.058221b57d4d2
setuptools@46.1.3
65.5.1
2
hookiesolutions/webhookie:latest0629694246ba
setuptools@45.2.0-1
45.2.0-1ubuntu0.1
2
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
setuptools@41.0.1
65.5.1
2
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
setuptools@41.0.1
65.5.1
2
jvstein/bitcoin-prometheus-exporter:v0.6.07645ba790ea8
setuptools@57.0.0
65.5.1
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
setuptools@58.1.0
65.5.1
2
larribas/mlflow:1.9.105ccb0b46bfb
setuptools@46.1.3
65.5.1
2
library/mysql:8.2.0212fe73edca5
setuptools@50.3.2
65.5.1
2
library/python:3.7.0-alpine3.8e12594db7297
setuptools@40.4.3
65.5.1
2
library/python:3.7eedf63967cdb
setuptools@57.5.0
65.5.1
2
library/python:3.7-alpinef3d31c8677d0
setuptools@57.5.0
65.5.1
2
lncm/specter-desktop:v1.10.536eaa06f99f4
setuptools@57.4.0
65.5.1
2
locustio/locust:2.32.2a0d4b88e42c1
setuptools@65.5.0
65.5.1
2
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1
2
minio/operator:v4.3.754393e03f3b2
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
2
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
setuptools@40.2.0
65.5.1
2
ncsa/checks:1.0.0abf6300b57b7
setuptools@49.2.1
65.5.1
2
neilpeterson/azure-vote-front:v384062718347c
setuptools@38.2.4
65.5.1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.